1. Scope and who we are
CreatoPost AI is a LinkedIn-focused content creation and publishing platform. This Privacy Policy applies to our marketing website, authenticated web application, free tools, LinkedIn integrations, payment flows, customer support interactions, and other services that link to or reference this policy. When we say "CreatoPost AI," "we," "us," or "our," we mean the operator of the CreatoPost AI service available through creatopost.ai and related product surfaces.
This policy covers personal information we process as a business or service provider in connection with operating the platform. It does not cover third-party websites, services, or policies that we do not control, even when those services are linked from our product. If you use LinkedIn, Razorpay, Google Analytics-enabled pages, or other third-party tools in connection with our service, those providers may process data under their own terms and privacy notices in addition to this policy.
By using the service, you acknowledge that we may process information as described in this policy. If you are using the service on behalf of a business, team, or client, you are responsible for making sure you have the authority to provide the information and instruct us to process it on your behalf.
2. Information we collect
We collect information directly from you, automatically from your use of the service, and from connected providers such as LinkedIn and payment or infrastructure partners. The exact categories depend on how you use CreatoPost AI. For example, a visitor using the public website may provide much less data than a registered user who connects LinkedIn, purchases credits, generates content, and enables analytics features.
The categories of information we collect can include the following:
- Account and identity data, such as your name, email address, encrypted password record, referral code details, and account preferences.
- Profile and onboarding data, such as your niche, topics, content preferences, and information you add while setting up or using the service.
- LinkedIn-connected data, such as your LinkedIn identifier, headline, profile photo, public profile details, access tokens, refresh tokens, posting permissions, and imported performance data when available.
- Content and workflow data, such as prompts, drafts, generated posts, uploaded images or media links, approval status, publishing schedules, and post performance metrics.
- Commercial data, such as credit purchases, Razorpay order and payment identifiers, payment status, invoices or transaction logs, and referral reward records.
- Technical and device data, such as browser type, approximate location derived from IP address, log and error data, request timestamps, and authentication or rate-limit events.
- Communication data, such as support emails, password reset requests, onboarding emails, billing notices, and product notifications.
We also infer limited information from usage patterns so the service works correctly. For example, we may infer whether you are logged in, whether a LinkedIn connection is active, whether credits are running low, whether a scheduled post failed to publish, or whether a particular feature needs abuse prevention or troubleshooting. We do not treat this operational inference as a separate category of data for marketing purposes, but we do use it to keep the service functioning and secure.
3. LinkedIn and other integrations
When you connect LinkedIn, we request access that allows us to authenticate your account, retrieve identity and profile information associated with the scopes you authorize, publish approved posts on your behalf, refresh access when needed, and collect related publishing or analytics data where available. The data returned by LinkedIn may include your name, email address, LinkedIn member identifier, public profile details, profile image, headline, and other metadata made available through the integration.
We store LinkedIn tokens and related identifiers so we can continue operating the integration you asked us to provide. Token storage is used to support publishing, profile sync, session continuity, and analytics import workflows. If LinkedIn revokes a token, if the token expires, or if permissions change, we may clear the stored token, prompt you to reconnect, and send an operational notice explaining what happened.
In addition to LinkedIn, our service uses third-party providers to process payments, deliver email, analyze traffic, and run AI-assisted generation workflows. These providers receive only the information reasonably necessary for the service they perform. The providers we currently rely on or route through may include:
- LinkedIn, to authenticate your account, import profile information, publish approved content, and retrieve analytics or related platform data when the feature is enabled.
- Razorpay, to create payment orders, verify completed purchases, reconcile payment events, and maintain transaction records.
- Anthropic and other AI model providers accessed through our service stack, including OpenAI-compatible endpoints used for generation workflows, to create or transform content based on your prompts and settings.
- Google Analytics, to measure traffic, understand usage of marketing pages, and improve site performance and conversion flows.
- Email and infrastructure providers, including SMTP-based delivery services and cloud hosting tools, to send account emails and operate the platform.
Third-party providers may act as independent controllers for some activities and as processors or service providers for others. For example, Razorpay applies its own compliance rules to payment information, LinkedIn applies its own platform rules to OAuth and publishing activity, and Google may process telemetry subject to its own controls. We encourage you to review the privacy notices of those providers when the integration matters to your use of the service.
4. How we use information
We use personal information to operate, maintain, improve, secure, and support CreatoPost AI. This includes providing the services you request, authenticating users, generating and storing content drafts, scheduling or publishing approved posts, analyzing performance, processing purchases, sending transactional notifications, and maintaining account history and credit balances.
More specifically, we may use information to create and manage your account; verify login credentials; issue access and refresh tokens; prevent fraud and abuse; monitor rate limits; process password reset requests; send onboarding, billing, referral, publishing, and security-related emails; reconcile payment records; administer free tools; and troubleshoot failures in API, publishing, analytics, or content-generation workflows.
We also use information to improve the service. That includes understanding which pages and features are used, how users reach the site, what content workflows succeed or fail, where security or reliability issues appear, and how we should prioritize product changes. Improvement activities may involve aggregate reporting, internal analytics, debugging, testing, and model-quality review. Where reasonable, we use de-identified or aggregated information for these purposes.
We may use limited contact information to send marketing or product-update messages where permitted by law, but we do not need that consent to send core service messages such as password resets, purchase confirmations, quota notices, failed publication alerts, or changes that materially affect your account. You can opt out of non-essential promotional emails using the unsubscribe mechanism in those messages.
5. Legal bases for processing
If privacy law in your jurisdiction requires a legal basis for processing, we rely on one or more of the following grounds depending on the context. First, we process data when necessary to perform a contract or take steps at your request before entering a contract, such as creating an account, authenticating you, processing a purchase, storing drafts, or publishing approved content through LinkedIn.
Second, we process certain information based on our legitimate interests, including securing the service, preventing fraud, maintaining system logs, debugging product failures, measuring site performance, improving quality, enforcing our terms, and understanding how users interact with our website and platform. When we rely on legitimate interests, we consider the impact on users and use the least intrusive approach that is reasonably available to accomplish the purpose.
Third, we may process information based on consent where required, such as certain analytics or marketing activities, or when you choose to connect LinkedIn or otherwise authorize an integration. Where processing is based on consent, you may withdraw that consent at any time, although doing so will not affect processing that occurred before withdrawal and may limit features that depend on the integration.
Finally, we may process information where necessary to comply with legal obligations, including tax, accounting, security, fraud-prevention, recordkeeping, or lawful access requests from public authorities.
7. Payments and commercial records
If you buy credits or other paid features, payment processing is handled through Razorpay and related payment infrastructure. We do not need to store your full card number on our own servers to complete a purchase. However, we do store transaction metadata such as order identifiers, payment identifiers, purchase amount, currency, credits purchased, payment status, and related webhook or audit records so we can confirm your purchase, maintain your credit balance, support refunds or disputes where applicable, and meet accounting obligations.
Payment records may also include raw payment event payloads or reconciliation details returned to us by Razorpay, subject to the controls in our systems and those of the payment provider. We use this data for fraud prevention, customer support, financial reporting, and operational integrity. If a payment fails or a webhook indicates a reversal, cancellation, or refund, we may update the status of the transaction and the credits available in your account accordingly.
Because financial recordkeeping may be required by law, we may retain some purchase and billing records even if you later close your account or request deletion of other information. Where possible, we will separate those legally required records from data that can be deleted sooner.
8. AI processing and generated content
CreatoPost AI processes prompts, profile details, user-selected themes, generated text, image prompts, workflow settings, and related content instructions so we can produce posts, images, strategic suggestions, and analytics-oriented recommendations. Some of this processing is performed using third-party model providers that receive the inputs required to generate an output. This means content that you submit through the product may be transmitted to those providers for inference and service delivery.
We use AI-processing inputs to generate requested outputs, improve workflow reliability, debug failures, maintain usage logs, and evaluate the quality and safety of our generation pipeline. We do not promise that AI-generated outputs are error-free, complete, or legally sufficient for every business purpose. Users remain responsible for reviewing generated content before publishing it, especially where factual accuracy, intellectual property, advertising standards, platform rules, or regulated content concerns may apply.
If you submit personal information, confidential business information, or third-party content into prompts or connected profile data, you are instructing us to process that information to provide the service. You should avoid submitting sensitive information that is unnecessary for the requested task. We may store generated outputs, drafts, prompts, and approval history in your account so they remain available for reuse, scheduling, analytics, support, and service continuity.
10. International data transfers
CreatoPost AI and the providers we use may process personal information in countries other than the one where you live. That can happen because cloud hosting, model providers, analytics vendors, email providers, or platform partners operate across multiple regions. As a result, your information may be transferred to and processed in jurisdictions that may not provide the same level of legal protection as your home country.
Where required by law, we take reasonable steps to use appropriate transfer mechanisms and safeguards for cross-border data movement. Depending on the provider and the legal relationship involved, those safeguards may include contractual commitments, technical and organizational controls, access limitations, and security reviews proportionate to the nature of the processing.
11. Data retention
We keep personal information only for as long as reasonably necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law. Retention periods vary depending on the category of data, the sensitivity of the information, the reason we collected it, whether the data is tied to an active account, and whether we must keep records for security, accounting, fraud prevention, dispute resolution, or legal compliance.
By way of example, we generally retain account profile information, content drafts, LinkedIn connection metadata, and workflow history while your account remains active and for a reasonable period afterward to support recovery, support, and compliance. Authentication data, refresh tokens, and operational logs may be deleted or rotated on shorter schedules depending on system needs. Purchase and tax-related records may be retained longer where necessary for accounting or legal obligations. If you request deletion, we will delete or de-identify information that we are not legally required to keep, subject to technical and operational limitations.
12. Security measures
We use a combination of administrative, technical, and organizational safeguards designed to protect personal information from unauthorized access, disclosure, alteration, and destruction. These measures may include encrypted token storage, password hashing, access controls, authentication checks, environment-based secrets management, request validation, audit logging, rate limiting, and operational monitoring for suspicious or abusive activity.
No internet-based service is perfectly secure, and we cannot guarantee absolute security. Users also play an important role in protecting their accounts. You should use a strong password, keep credentials confidential, protect your devices, review account activity, and reconnect or revoke third-party integrations if you believe access has been compromised. If we become aware of a security incident affecting personal information, we will investigate and provide notice where required by law.
13. Your choices and account controls
You can access, update, or correct certain information through your account settings or by contacting us. You may disconnect LinkedIn, change profile details, review drafts, manage approvals, stop using paid features, or request account deletion. You may also choose not to provide certain data, but some features of the platform will not work without it. For example, we cannot publish posts to LinkedIn without a valid LinkedIn connection and the required platform permissions.
If you no longer want to receive promotional communications, you can use the unsubscribe link in those messages or contact us directly. Please note that you may still receive transactional or service-related communications that are necessary to operate your account, such as password reset emails, billing notices, LinkedIn reconnection alerts, or important updates about changes to the service.
Browser and device settings may also let you control cookies, local storage, and other tracking technologies. Because some of those controls are outside our systems, you may need to adjust them directly in your browser or device. Turning off certain technologies may reduce functionality.
14. EEA, UK, and similar privacy rights
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with comparable rights, you may have the right to request access to the personal information we hold about you, request correction of inaccurate data, request deletion of data in certain circumstances, object to certain processing, request restriction of processing, and request portability of the data you provided to us in a structured, commonly used format where technically feasible.
You may also have the right to withdraw consent where we rely on consent as the legal basis for processing. Withdrawal does not affect the lawfulness of processing that took place before the withdrawal. We may need to retain some information where permitted or required by law, where another lawful basis applies, or where the data is needed to complete a transaction, detect security incidents, defend legal claims, or comply with accounting and recordkeeping obligations.
To exercise these rights, email [email protected] with enough information for us to identify your account and understand the request. We may ask for additional information to verify your identity before acting on a request. If you believe we have not handled your request appropriately, you may also have the right to complain to the privacy or data-protection authority in your place of residence.
15. U.S. state privacy rights
Residents of certain U.S. states, including California, Colorado, Connecticut, Utah, Virginia, and other states with applicable privacy laws, may have rights to know what categories of personal information we collect, access specific pieces of information, correct inaccurate information, delete personal information, and opt out of certain types of processing, subject to exemptions and verification requirements.
Depending on the law that applies to you, you may also have the right to appeal a decision we make about your request. California residents may request information about the categories of personal information collected, sources of collection, business or commercial purposes for use, categories of recipients, and categories of information disclosed for business purposes during the relevant lookback period. We do not use your account information to sell personal information for cash consideration. However, some analytics and advertising-related disclosures by third-party technologies can be treated as "sharing" under certain state laws, and you may exercise available opt-out choices where applicable.
We will not discriminate against you for exercising a privacy right in a manner prohibited by law. To submit a request, email [email protected] and describe the right you want to exercise. We may need to verify your identity or authority before completing the request.
16. Children's privacy
CreatoPost AI is intended for adults and business users, not children. We do not knowingly collect personal information from children under the age for digital consent in the relevant jurisdiction, and the service is not directed to them. If you believe a child has provided personal information to us, contact [email protected] so we can investigate and, where appropriate, delete the information.
17. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in the service, the law, our providers, or our operational practices. When we make material changes, we will update the "Last updated" date at the top of the page and may provide additional notice through the website, product interface, or email where appropriate.
Your continued use of the service after an updated policy becomes effective means the updated policy applies to future use of the service, subject to any additional rights you may have under applicable law.
18. Contact information
If you have questions about this Privacy Policy, want to exercise a privacy right, or need to report a privacy or security concern, contact us at [email protected].
Please include enough detail for us to understand your request, the email address or account connected to your use of CreatoPost AI, and the jurisdiction you are contacting us from if your request relies on a specific privacy law. We may request additional information to verify identity before disclosing, deleting, or modifying account data.